Permission is not consent.It is only access.

The operating system asks if you may. The Act asks why.

In one line: No, not by itself. A permission grants technical access. DPDPA requires a notice of the purpose and consent that is free, specific, informed and unambiguous. Apps should show their own notice alongside permissions.

The estate · Fintech & NBFCHover to inspect

‘Allow’ opens the door. It does not tell the customer what you will do inside.

The scene

The permission screen appeared before the customer had typed her name. Contacts, SMS, location, storage. She tapped Allow four times because the loan was urgent. Six months later she asked the app what it knew about her. The answer ran to eleven categories she had never heard of.

Where the thinking breaks

The unclear thoughtWhat it breaksThe clearer thought
The OS permission dialog is our consent. It names a capability, not a purpose; DPDPA requires notice of purpose and specific consent. Show your own notice before the OS dialog: what, why, and what happens if she says no.
Without permissions the app won't work. Section 6 bars conditioning a service on consent to data it does not need. Ask only for what the loan needs. Ask later for anything else.

What regulators already said

The RBI's digital lending framework already restricts lending apps from accessing contacts, media and call logs beyond one-time needs. DPDPA adds the general rule: necessity for the stated purpose.

Monday morning

  1. 01List every permission your app requests.
  2. 02Write the purpose for each in one line a customer would understand.
  3. 03Remove any you cannot justify.

Questions, answered plainly

Is an app permission valid consent under DPDPA?

No, not by itself. A permission grants technical access. DPDPA requires a notice of the purpose and consent that is free, specific, informed and unambiguous. Apps should show their own notice alongside permissions.

Can a lending app access a borrower's contact list?

RBI's digital lending rules restrict access to contacts, media and call logs. DPDPA separately requires the data to be necessary for the stated purpose.

Sector · Fintech & NBFCYour onboarding takes ninety seconds. Your liability lasts years.Read → Fintech & NBFC · Deep diveThe model knows things the customer was never told.Read → Fintech & NBFC · Deep diveThe consent model already exists. Copy it.Read →

Tell us where your data sits.We'll show you where the exposure is.

A partner replies within one working day, with a first view on your penalty exposure.

Speak to a partner